Blame SOURCES/autofs-5.1.0-fix-memory-leak-in-get_exports.patch

4d476f
autofs-5.1.0 - fix memory leak in get_exports()
4d476f
4d476f
From: Ian Kent <ikent@redhat.com>
4d476f
4d476f
In modules/lookup_hosts.c:get_exports() looping over the returned list of
4d476f
exports uses the pointer that contains the list. The pointer is updated
4d476f
in the process of creating the exports multi-mount so a pointer to the
4d476f
returned list is no longer available to be freed when done.
4d476f
---
4d476f
 CHANGELOG              |    1 +
4d476f
 modules/lookup_hosts.c |   17 +++++++++--------
4d476f
 2 files changed, 10 insertions(+), 8 deletions(-)
4d476f
4d476f
--- autofs-5.0.7.orig/CHANGELOG
4d476f
+++ autofs-5.0.7/CHANGELOG
4d476f
@@ -149,6 +149,7 @@
4d476f
 - force disable browse mode for amd format maps.
4d476f
 - fix hosts map options check in lookup_amd_instance().
4d476f
 - fix memory leak in create_client().
4d476f
+- fix memory leak in get_exports().
4d476f
 
4d476f
 25/07/2012 autofs-5.0.7
4d476f
 =======================
4d476f
--- autofs-5.0.7.orig/modules/lookup_hosts.c
4d476f
+++ autofs-5.0.7/modules/lookup_hosts.c
4d476f
@@ -82,18 +82,19 @@ static char *get_exports(struct autofs_p
4d476f
 {
4d476f
 	char buf[MAX_ERR_BUF];
4d476f
 	char *mapent;
4d476f
-	exports exp;
4d476f
+	exports exp, this;
4d476f
 
4d476f
 	debug(ap->logopt, MODPREFIX "fetchng export list for %s", host);
4d476f
 
4d476f
 	exp = rpc_get_exports(host, 10, 0, RPC_CLOSE_NOLINGER);
4d476f
 
4d476f
 	mapent = NULL;
4d476f
-	while (exp) {
4d476f
+	this = exp;
4d476f
+	while (this) {
4d476f
 		if (mapent) {
4d476f
 			int len = strlen(mapent) + 1;
4d476f
 
4d476f
-			len += strlen(host) + 2*(strlen(exp->ex_dir) + 2) + 3;
4d476f
+			len += strlen(host) + 2*(strlen(this->ex_dir) + 2) + 3;
4d476f
 			mapent = realloc(mapent, len);
4d476f
 			if (!mapent) {
4d476f
 				char *estr;
4d476f
@@ -103,10 +104,10 @@ static char *get_exports(struct autofs_p
4d476f
 				return NULL;
4d476f
 			}
4d476f
 			strcat(mapent, " \"");
4d476f
-			strcat(mapent, exp->ex_dir);
4d476f
+			strcat(mapent, this->ex_dir);
4d476f
 			strcat(mapent, "\"");
4d476f
 		} else {
4d476f
-			int len = 2*(strlen(exp->ex_dir) + 2) + strlen(host) + 3;
4d476f
+			int len = 2*(strlen(this->ex_dir) + 2) + strlen(host) + 3;
4d476f
 
4d476f
 			mapent = malloc(len);
4d476f
 			if (!mapent) {
4d476f
@@ -117,16 +118,16 @@ static char *get_exports(struct autofs_p
4d476f
 				return NULL;
4d476f
 			}
4d476f
 			strcpy(mapent, "\"");
4d476f
-			strcat(mapent, exp->ex_dir);
4d476f
+			strcat(mapent, this->ex_dir);
4d476f
 			strcat(mapent, "\"");
4d476f
 		}
4d476f
 		strcat(mapent, " \"");
4d476f
 		strcat(mapent, host);
4d476f
 		strcat(mapent, ":");
4d476f
-		strcat(mapent, exp->ex_dir);
4d476f
+		strcat(mapent, this->ex_dir);
4d476f
 		strcat(mapent, "\"");
4d476f
 
4d476f
-		exp = exp->ex_next;
4d476f
+		this = this->ex_next;
4d476f
 	}
4d476f
 	rpc_exports_free(exp);
4d476f